monkey-project kayıtları
monkey-project üreticisine ait 29 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %3,4
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation6
- CWE-125 Out-of-bounds Read5
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-416 Use After Free2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
29 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2013-2159İstismar yok | Monkey HTTP Daemon: broken user name authenticationmonkey-project · monkey · CWE-287 | Kritik9,8 | — | %2,8 | 10 Ara 2019 |
33İzleyin | CVE-2013-3843Silahlaştırılmış | Stack-based buffer overflow in the mk_request_header_process function in mk_request.c in Monkey HTTP Daemon (monkeyd) before 1.2.1 allows remonkey-project · monkey · CWE-119 | Orta6,8 | — | %20,2 | 13 Haz 2014 |
33İzleyin | CVE-2025-63655İstismar yok | A NULL pointer dereference in the mk_http_range_parse function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Demonkey-project · monkey · CWE-476 | Yüksek7,5 | — | %8,6 | 29 Oca 2026 |
32İzleyin | CVE-2003-0218İstismar yok | Buffer overflow in PostMethod() function for Monkey HTTP Daemon (monkeyd) 0.6.1 and earlier allows remote attackers to execute arbitrary codmonkey-project · monkey · CWE-119 | Yüksek7,5 | — | %5,2 | 12 May 2003 |
31İzleyin | CVE-2013-1771İstismar yok | The web server Monkeyd produces a world-readable log (/var/log/monkeyd/master.log) on gentoo.monkey-project · monkey · CWE-532 | Yüksek7,5 | — | %3,0 | 7 Kas 2019 |
31İzleyin | CVE-2005-1122İstismar yok | Format string vulnerability in cgi.c for Monkey daemon (monkeyd) before 0.9.1 allows remote attackers to cause a denial of service and possimonkey-project · monkey · CWE-134 | Yüksek7,5 | — | %2,7 | 14 Nis 2005 |
30İzleyin | CVE-2025-63658İstismar yok | A stack overflow in the mk_http_index_lookup function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Smonkey-project · monkey · CWE-121 | Yüksek7,5 | — | %1,3 | 29 Oca 2026 |
30İzleyin | CVE-2025-63656İstismar yok | An out-of-bounds read in the header_cmp function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers to cause a Denial ofmonkey-project · monkey · CWE-125 | Yüksek7,5 | — | %1,2 | 29 Oca 2026 |
30İzleyin | CVE-2025-63650İstismar yok | An out-of-bounds read in the mk_ptr_to_buf in mk_core function (mk_memory.c) of monkey commit f37e984 allows attackers to cause a Denial of monkey-project · monkey · CWE-125 | Yüksek7,5 | — | %1,2 | 29 Oca 2026 |
30İzleyin | CVE-2025-63652İstismar yok | A use-after-free in the mk_http_request_end function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Semonkey-project · monkey · CWE-416 | Yüksek7,5 | — | %1,2 | 29 Oca 2026 |
30İzleyin | CVE-2025-63653İstismar yok | An out-of-bounds read in the mk_vhost_fdt_close function (mk_server/mk_vhost.c) of monkey commit f37e984 allows attackers to cause a Denial monkey-project · monkey · CWE-125 | Yüksek7,5 | — | %1,2 | 29 Oca 2026 |
30İzleyin | CVE-2025-63657İstismar yok | An out-of-bounds read in the mk_mimetype_find function (mk_server/mk_mimetype.c) of monkey commit f37e984 allows attackers to cause a Denialmonkey-project · monkey · CWE-125 | Yüksek7,5 | — | %1,2 | 29 Oca 2026 |
30İzleyin | CVE-2025-63649İstismar yok | An out-of-bounds read in the http_parser_transfer_encoding_chunked function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attmonkey-project · monkey · CWE-125 | Yüksek7,5 | — | %1,1 | 29 Oca 2026 |
30İzleyin | CVE-2025-63651İstismar yok | A use-after-free in the mk_string_char_search function (mk_core/mk_string.c) of monkey commit f37e984 allows attackers to cause a Denial of monkey-project · monkey · CWE-416 | Yüksek7,5 | — | %1,1 | 29 Oca 2026 |
28İzleyin | CVE-2013-2183İstismar yok | Monkey HTTP Daemon has local security bypassmonkey-project · monkey · CWE-668 | Yüksek7,1 | — | %0,4 | 10 Ara 2019 |
27İzleyin | CVE-2012-4443İstismar yok | Monkey HTTP Daemon 0.9.3 uses a real UID of root and a real GID of root during execution of CGI scripts, which might allow local users to gamonkey-project · monkey · CWE-264 | Orta6,9 | — | %0,4 | 5 Eki 2012 |
27İzleyin | CVE-2012-5303İstismar yok | Monkey HTTP Daemon 0.9.3 might allow local users to overwrite arbitrary files via a symlink attack on a PID file, as demonstrated by a pathnmonkey-project · monkey · CWE-59 | Orta6,9 | — | %0,3 | 5 Eki 2012 |
25İzleyin | CVE-2013-2182Kavram kanıtı | The Mandril security plugin in Monkey HTTP Daemon (monkeyd) before 1.5.0 allows remote attackers to bypass access restrictions via a craftedmonkey-project · monkey · CWE-264 | Orta5,8 | — | %5,6 | 13 Haz 2014 |
24İzleyin | CVE-2013-3724Kavram kanıtı | The mk_request_header_process function in mk_request.c in Monkey 1.1.1 allows remote attackers to cause a denial of service (thread crash anmonkey-project · monkey · CWE-20 | Orta5,0 | — | %13,7 | 1 Ağu 2013 |
22İzleyin | CVE-2002-2154Kavram kanıtı | Directory traversal vulnerability in Monkey HTTP Daemon 0.1.4 allows remote attackers to read arbitrary files via ..monkey-project · monkey · CWE-22 | Orta5,0 | — | %7,6 | 31 Ara 2002 |
21İzleyin | CVE-2002-1663Kavram kanıtı | The Post_Method function in method.c for Monkey HTTP Daemon before 0.5.1 allows remote attackers to cause a denial of service (crash) via a monkey-project · monkey · CWE-20 | Orta5,0 | — | %4,0 | 31 Ara 2002 |
21İzleyin | CVE-2004-0276Kavram kanıtı | The get_real_string function in Monkey HTTP Daemon (monkeyd) 0.8.1 and earlier allows remote attackers to cause a denial of service (crash) monkey-project · monkey · CWE-20 | Orta5,0 | — | %3,7 | 23 Kas 2004 |
21İzleyin | CVE-2013-2163İstismar yok | Monkey HTTP Daemon (monkeyd) before 1.2.2 allows remote attackers to cause a denial of service (infinite loop) via an offset equal to the fimonkey-project · monkey · CWE-20 | Orta5,0 | — | %2,5 | 13 Haz 2014 |
21İzleyin | CVE-2003-1209İstismar yok | The Post_Method function in Monkey HTTP Daemon before 0.6.2 allows remote attackers to cause a denial of service (crash) via a POST request monkey-project · monkey · CWE-20 | Orta5,0 | — | %2,4 | 31 Ara 2003 |
20İzleyin | CVE-2005-1123İstismar yok | Monkey daemon (monkeyd) before 0.9.1 allows remote attackers to cause a denial of service (memory corruption) via a request for a zero byte monkey-project · monkey · CWE-119 | Orta5,0 | — | %1,6 | 2 May 2005 |
- CVE-2013-215940Planlayın
Monkey HTTP Daemon: broken user name authentication
KritikCVSS 9,8İstismar yokEPSS %3monkey-project · monkey10 Ara 2019
- CVE-2013-384333İzleyin
Stack-based buffer overflow in the mk_request_header_process function in mk_request.c in Monkey HTTP Daemon (monkeyd) before 1.2.1 allows re
OrtaCVSS 6,8SilahlaştırılmışEPSS %20monkey-project · monkey13 Haz 2014
- CVE-2025-6365533İzleyin
A NULL pointer dereference in the mk_http_range_parse function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a De
YüksekCVSS 7,5İstismar yokEPSS %9monkey-project · monkey29 Oca 2026
- CVE-2003-021832İzleyin
Buffer overflow in PostMethod() function for Monkey HTTP Daemon (monkeyd) 0.6.1 and earlier allows remote attackers to execute arbitrary cod
YüksekCVSS 7,5İstismar yokEPSS %5monkey-project · monkey12 May 2003
- CVE-2013-177131İzleyin
The web server Monkeyd produces a world-readable log (/var/log/monkeyd/master.log) on gentoo.
YüksekCVSS 7,5İstismar yokEPSS %3monkey-project · monkey7 Kas 2019
- CVE-2005-112231İzleyin
Format string vulnerability in cgi.c for Monkey daemon (monkeyd) before 0.9.1 allows remote attackers to cause a denial of service and possi
YüksekCVSS 7,5İstismar yokEPSS %3monkey-project · monkey14 Nis 2005
- CVE-2025-6365830İzleyin
A stack overflow in the mk_http_index_lookup function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of S
YüksekCVSS 7,5İstismar yokEPSS %1monkey-project · monkey29 Oca 2026
- CVE-2025-6365630İzleyin
An out-of-bounds read in the header_cmp function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers to cause a Denial of
YüksekCVSS 7,5İstismar yokEPSS %1monkey-project · monkey29 Oca 2026
- CVE-2025-6365030İzleyin
An out-of-bounds read in the mk_ptr_to_buf in mk_core function (mk_memory.c) of monkey commit f37e984 allows attackers to cause a Denial of
YüksekCVSS 7,5İstismar yokEPSS %1monkey-project · monkey29 Oca 2026
- CVE-2025-6365230İzleyin
A use-after-free in the mk_http_request_end function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Se
YüksekCVSS 7,5İstismar yokEPSS %1monkey-project · monkey29 Oca 2026
- CVE-2025-6365330İzleyin
An out-of-bounds read in the mk_vhost_fdt_close function (mk_server/mk_vhost.c) of monkey commit f37e984 allows attackers to cause a Denial
YüksekCVSS 7,5İstismar yokEPSS %1monkey-project · monkey29 Oca 2026
- CVE-2025-6365730İzleyin
An out-of-bounds read in the mk_mimetype_find function (mk_server/mk_mimetype.c) of monkey commit f37e984 allows attackers to cause a Denial
YüksekCVSS 7,5İstismar yokEPSS %1monkey-project · monkey29 Oca 2026
- CVE-2025-6364930İzleyin
An out-of-bounds read in the http_parser_transfer_encoding_chunked function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows att
YüksekCVSS 7,5İstismar yokEPSS %1monkey-project · monkey29 Oca 2026
- CVE-2025-6365130İzleyin
A use-after-free in the mk_string_char_search function (mk_core/mk_string.c) of monkey commit f37e984 allows attackers to cause a Denial of
YüksekCVSS 7,5İstismar yokEPSS %1monkey-project · monkey29 Oca 2026
- CVE-2013-218328İzleyin
Monkey HTTP Daemon has local security bypass
YüksekCVSS 7,1İstismar yokEPSS %0monkey-project · monkey10 Ara 2019
- CVE-2012-444327İzleyin
Monkey HTTP Daemon 0.9.3 uses a real UID of root and a real GID of root during execution of CGI scripts, which might allow local users to ga
OrtaCVSS 6,9İstismar yokEPSS %0monkey-project · monkey5 Eki 2012
- CVE-2012-530327İzleyin
Monkey HTTP Daemon 0.9.3 might allow local users to overwrite arbitrary files via a symlink attack on a PID file, as demonstrated by a pathn
OrtaCVSS 6,9İstismar yokEPSS %0monkey-project · monkey5 Eki 2012
- CVE-2013-218225İzleyin
The Mandril security plugin in Monkey HTTP Daemon (monkeyd) before 1.5.0 allows remote attackers to bypass access restrictions via a crafted
OrtaCVSS 5,8Kavram kanıtıEPSS %6monkey-project · monkey13 Haz 2014
- CVE-2013-372424İzleyin
The mk_request_header_process function in mk_request.c in Monkey 1.1.1 allows remote attackers to cause a denial of service (thread crash an
OrtaCVSS 5,0Kavram kanıtıEPSS %14monkey-project · monkey1 Ağu 2013
- CVE-2002-215422İzleyin
Directory traversal vulnerability in Monkey HTTP Daemon 0.1.4 allows remote attackers to read arbitrary files via ..
OrtaCVSS 5,0Kavram kanıtıEPSS %8monkey-project · monkey31 Ara 2002
- CVE-2002-166321İzleyin
The Post_Method function in method.c for Monkey HTTP Daemon before 0.5.1 allows remote attackers to cause a denial of service (crash) via a
OrtaCVSS 5,0Kavram kanıtıEPSS %4monkey-project · monkey31 Ara 2002
- CVE-2004-027621İzleyin
The get_real_string function in Monkey HTTP Daemon (monkeyd) 0.8.1 and earlier allows remote attackers to cause a denial of service (crash)
OrtaCVSS 5,0Kavram kanıtıEPSS %4monkey-project · monkey23 Kas 2004
- CVE-2013-216321İzleyin
Monkey HTTP Daemon (monkeyd) before 1.2.2 allows remote attackers to cause a denial of service (infinite loop) via an offset equal to the fi
OrtaCVSS 5,0İstismar yokEPSS %3monkey-project · monkey13 Haz 2014
- CVE-2003-120921İzleyin
The Post_Method function in Monkey HTTP Daemon before 0.6.2 allows remote attackers to cause a denial of service (crash) via a POST request
OrtaCVSS 5,0İstismar yokEPSS %2monkey-project · monkey31 Ara 2003
- CVE-2005-112320İzleyin
Monkey daemon (monkeyd) before 0.9.1 allows remote attackers to cause a denial of service (memory corruption) via a request for a zero byte
OrtaCVSS 5,0İstismar yokEPSS %2monkey-project · monkey2 May 2005